7wData Ins7ghts

If this landed in Promotions or Other, move it to your main inbox. One move keeps it there.

So, What Actually Happened?

Thursday, and I keep going back to one line in a court notice. The Supreme Court of Ohio says a vendor told it in July about a March breach, and this week the court still cannot say whose data walked out. We scanned 190,000 articles this week so you don't have to. Same forty-eight hours: Washington pushed a looser AI rulebook while Brussels wrote a stricter one, and Reuters had two large law firms breached. I went in looking for the governance story and expected policy. What I found was handoffs. Every one of these is a moment where one organisation waits on another to tell it the truth, on time, and that is exactly where it broke.

The Bottom Line: Governance is the loudest word in the industry right now, and it keeps failing at the same place: the seam between you and whoever you depend on.

MinIO AIStor gives Databricks live, zero-copy access to your on-prem data—regulated, petabyte-scale, real-time. No replication, no pipelines, no downsampling. See how enterprises connect Databricks to data that never left home.

The Tracks That Matter

1. Ohio's Courts Learned About A March Breach In July

The Supreme Court of Ohio says unauthorized access hit the production platform holding filings for ten of its twelve Courts of Appeals. The incident happened in March. The vendor notified the court on July 24. On August 31 the court was told it was the production system, not a test copy, and it still has not been given full detail on what was fixed or which people were exposed. Other states running the same case management software are affected. In the same window Reuters reported two large law firms breached, Herbert Smith and Goodwin. Notice what both share: the data was safe inside the organisation that owned it, and it left through the supplier hired to handle it.

Here's what works: List the five vendors touching your regulated data. Next to each, write the contractual notification window and the last date they actually met it.

PARTNER
The Most Daring CFO Transformation: a $310M bet turned into a $3.6B outcome. Read the story.

A $310M bet nobody liked. A $3.6B outcome.

Acxiom overpaid for LiveRamp, by their own CFO's admission. Then they sold the business holding 75% of the staff and 100% of the cash flow, and kept the one that was not earning yet. Warren Jenson (ex-CFO at Amazon, Delta, NBC) on how he got the board there.

Read the full story →

Free download, registration required.

2. Washington Loosens The AI Rulebook While Brussels Writes A New One

The split is official now. The US is pushing a looser approach to AI regulation while the EU pushes new law, which means anyone operating on both sides now runs two compliance postures for the same model. Europe is not being theoretical about it: the AI Act's obligations keep landing through 2026, and the privacy regime that came before it has already collected €7.1 billion in fines. Write one policy and hope it travels, and it will travel to exactly one of your markets. The teams handling this well stopped writing regional policies and started writing controls with a jurisdiction flag, so the same pipeline behaves differently in Frankfurt than it does in Texas.

Here's what works: Take one line of your AI policy and turn it into a control with a jurisdiction flag. One that runs beats twelve that sit in a folder.

3. A German Rocket Startup Raised €50 Million On Fewer Parts

HyImpulse, a 2018 spin-out from Germany's national aerospace lab, raised €50 million on a hybrid design using roughly half the parts of a conventional rocket and paraffin for fuel. CEO Christian Schmierer is blunt about the field: everyone else is rebuilding what American companies already built, on propulsion from the 1960s. The part that makes this more than a space story is the order book, around €350 million of committed launch services against about €125 million raised in total. Committed demand ahead of committed capital. Meanwhile in warehouse robotics, Geek+ reported orders up 35.5% at the half year. Machines with signed orders are having a very different year than software with signed pilots.

Here's what works: Split your AI spend into committed and exploratory. If nothing has a signed internal customer, that is a research budget, not a programme.

Quick hits:

  • Medicare wants to decide device coverage the day the FDA says yes. CMS proposed the RAPID coverage pathway, a same-day proposed decision with a final one 60 to 90 days later, replacing the slower TCET route. Speed is the point, and so is the catch: ”demonstrates improvement” is left undefined.
  • Physics got pointed at the power bill. Physical Superintelligence closed a $58 million seed to apply physics models to data centre efficiency, with the biggest compute buyers among the participants. That tells you where they think the next saving lives.
  • DNA as memory left the thought-experiment stage. Penn State researchers built energy-efficient memory from DNA aimed at AI workloads, the kind of result that looks irrelevant for years and then reprices a whole capex line.

Stop typing what you could say in 10 seconds.

Wispr Flow turns your voice into clean, professional text inside any app. Emails, Slack, client updates — speak once, send without editing. 4x faster than typing.

Signal vs. Noise

🟢 Signal: Data governance with a name attached. While everyone argued about AI policy, plain data governance gained real hold on the stories that moved: who owns which table, what the retention rule says, who has to call you when something goes wrong. That is the version that shows up in a breach notice, and almost nobody is covering it.

🔴 Noise: ”AI governance” as a label. It pulled heavy volume again this week while losing its grip on what actually happened underneath. Everyone is publishing an AI governance framework. Very few of them survive contact with a vendor who takes four months to explain a breach.

From the 190K

We scanned 190,000 articles this week. Here's what no one's talking about:

A state court could not get a straight answer from its software vendor, Washington and Brussels moved in opposite directions on AI law, and Medicare proposed deciding device coverage on the same day the FDA does, all inside forty-eight hours.

Three desks, three filings. The legal press writes Ohio as a breach notice. The geopolitics desk writes the US and EU as a trade story. The health-policy desk writes CMS as a reimbursement change. Read them on one morning and they are a single story about handoffs, the moment your organisation stops being in control and starts waiting on somebody else's process. The court waits on a vendor. The multinational waits on two regulators who now disagree with each other. The device maker waits on an agency that just compressed its own timeline and left a key criterion undefined. Almost every AI programme I have watched fail in the last two years failed at a handoff, not at a model.

What changes on Friday is small and specific. Take your largest AI or data initiative and draw its handoffs: every point where you wait on someone outside your walls. Next to each one, write the last date they actually delivered on time. Not the SLA, the real date. Most teams find one or two seams they have never measured, and an unmeasured seam is not a risk yet, it is a surprise looking for a spot in your calendar.

Voices designs, licenses, and captures your Branded AI Voice from real, consenting professional actors—never scraped data. Fully licensed, exclusively yours. Trusted by BMW and SuperBloom.

By The Numbers

Deep Dive: The Club With The Beautiful Safety Binder

A club in Antwerp, years back, handed me their safety binder before the set. Laminated pages, evacuation routes, a fire inspector's signature, the whole thing heavier than my record bag. Ninety minutes later the power died mid-track, because the fuse box behind the bar had been extended six times by six different electricians and nobody working that night could tell me which one to call.

The binder was real

Nobody lied to me. The procedures existed, somebody had genuinely written them, an inspector had genuinely signed. That is roughly the state of AI governance today: frameworks published, committees seated, policies approved. The document is real. What the document cannot do is fail a build or stop a deployment at 2am.

Nobody could name the electrician

The gap was ownership of the physical thing. Ohio's court had a vendor, a contract, presumably a security addendum. What it did not have was a name and a number that produced complete answers in under four months. Every handoff needs a person, not a clause.

The fault was old before anyone felt it

That fuse box had been wrong for a long time. It only became an emergency when the room was full. A March breach reported in July and still unresolved in September has the same shape. Time is not the problem. Silence is.

What Actually Works

  1. Name the electrician: every critical vendor gets one named human on your side who owns that relationship and one on theirs who answers the phone.
  2. Measure the seam: track actual notification and response times per vendor, not contractual ones. The gap between them is your real exposure.
  3. Compile one policy line: turn a single sentence of your AI policy into a control that runs in the pipeline and fails the build.
  4. Ask for it in writing: when a supplier says it is fixed, request what was fixed, when, and how it was verified. Their hesitation is data.

The binder passed the inspection. The fuse box ran the room.

What's Coming

Notification Windows Become A Contract Fight

The five-month gap in the Ohio court's breach timeline is going to get quoted in procurement meetings this autumn. Expect renewal negotiations where the notification clause, not the price, is the thing both sides argue about.

Two Rulebooks Become A Product Decision

With Washington loosening while Brussels tightens, the cost of maintaining one global model behaviour goes up. Some teams will ship regional variants of the same product. Others will quietly build to the strictest market and stop thinking about it, which is usually cheaper than it looks.

Regulators Start Competing On Speed

CMS proposing same-day coverage decisions is a regulator using velocity as policy. Once one agency does that publicly, the ones that take eighteen months start having to explain themselves.

For Your Team

Friday's meeting prompt: ”Name every outside party our AI and data work depends on to act: vendors, regulators, cloud providers. For each one, when did they last deliver on time, and who here would know if they didn't?”

Share-worthy stat: An American state court found out in July about a March breach of the system holding filings for ten of its twelve appeals courts. By September it still could not say whose data was exposed. Every vendor security review you have ever signed off assumes that gap is measured in days.

Go deeper: Track where AI governance and data spend are moving →

The Track of the Day

”The Court has been advised that enhanced and updated security measures have been deployed, but the Court has not yet received comprehensive details about such measures.”
Supreme Court of Ohio, statement on the C-Track incident

That is a sentence about a court and a software vendor, and it is also every vendor risk review I have sat through in twenty years. Somebody says it is fixed. Nobody can show you what was fixed.

We scanned 190,000 articles this week so you don't have to. Data Pains → Business Gains.

Published: September 3, 2026 | Curated by Yves Mulkers @ Ins7ghts

1,300+ articles scanned. 7 stories selected. Our AI distills the noise into signal—in seconds. Get early access →

Know someone who'd find this useful? Share your unique referral link →

Want Your Own AI Intelligence Briefing?

Our platform analyzes 1,000+ sources daily and delivers personalized insights in seconds.

Join the Waitlist →

Founding members: Lifetime discount • Priority access • Shape the product